All language subtitles for 2. Capture frames packets segments

af Afrikaans
ak Akan
sq Albanian
am Amharic
ar Arabic
hy Armenian
az Azerbaijani
eu Basque
be Belarusian
bem Bemba
bn Bengali
bh Bihari
bs Bosnian
br Breton
bg Bulgarian
km Cambodian
ca Catalan
ceb Cebuano
chr Cherokee
ny Chichewa
zh-CN Chinese (Simplified)
zh-TW Chinese (Traditional)
co Corsican
hr Croatian
cs Czech
da Danish
nl Dutch
en English
eo Esperanto
et Estonian
ee Ewe
fo Faroese
tl Filipino
fi Finnish
fr French
fy Frisian
gaa Ga
gl Galician
ka Georgian
de German
el Greek
gn Guarani
gu Gujarati
ht Haitian Creole
ha Hausa
haw Hawaiian
iw Hebrew
hi Hindi
hmn Hmong
hu Hungarian
is Icelandic
ig Igbo
ia Interlingua
ga Irish
it Italian
ja Japanese
jw Javanese
kn Kannada
kk Kazakh
rw Kinyarwanda
rn Kirundi
kg Kongo
ko Korean
kri Krio (Sierra Leone)
ku Kurdish
ckb Kurdish (Soranรฎ)
ky Kyrgyz
lo Laothian
la Latin
lv Latvian
ln Lingala
lt Lithuanian
loz Lozi
lg Luganda
ach Luo
lb Luxembourgish
mk Macedonian
mg Malagasy
ms Malay
ml Malayalam
mt Maltese
mi Maori
mr Marathi
mfe Mauritian Creole
mo Moldavian
mn Mongolian
my Myanmar (Burmese)
sr-ME Montenegrin
ne Nepali
pcm Nigerian Pidgin
nso Northern Sotho
no Norwegian
nn Norwegian (Nynorsk)
oc Occitan
or Oriya
om Oromo
ps Pashto
fa Persian
pl Polish
pt-BR Portuguese (Brazil)
pt Portuguese (Portugal) Download
pa Punjabi
qu Quechua
ro Romanian
rm Romansh
nyn Runyakitara
ru Russian
sm Samoan
gd Scots Gaelic
sr Serbian
sh Serbo-Croatian
st Sesotho
tn Setswana
crs Seychellois Creole
sn Shona
sd Sindhi
si Sinhalese
sk Slovak
sl Slovenian
so Somali
es Spanish
es-419 Spanish (Latin American)
su Sundanese
sw Swahili
sv Swedish
tg Tajik
ta Tamil
tt Tatar
te Telugu
th Thai
ti Tigrinya
to Tonga
lua Tshiluba
tum Tumbuka
tr Turkish
tk Turkmen
tw Twi
ug Uighur
uk Ukrainian
ur Urdu
uz Uzbek
vi Vietnamese
cy Welsh
wo Wolof
xh Xhosa
yi Yiddish
yo Yoruba
zu Zulu

Original subtitles

Okay so I'm gonna open up a web browser from P.S. 1 to the server the service IP address and this is

a linux server is 10 dot 1 dot wondered 100.

I used the command I have config to see the service IP address.

So what I'll do is start capturing traffic between the P.C. and the switch.

Genius 3 makes this very easy.

It allows us to capture traffic directly within the topology rather than having to install a hub or

a wire tap or something to see the traffic.

So I'm gonna capture the traffic between the P.C. and the switch and we'll be able to see exactly what's

going on within this why shock capture so you can see that we've got spanning tree traffic we've got

a job P traffic dynamic trunk protocol traffic already displayed and being captured by a y shock.

What I'm going to do however is falter for HDP.

There's no HDP traffic at the moment but what we'll do is open up a web browser on the P.C. and connect

it to the server so let's use P.S. 1 open up a web browser.

I'm going to browse to

tendered wondered one at 100 which is the server and as you can see they are web pages displayed.

That's nothing fancy it's just a basic Web page hosted on the server but it's enough for us to see what's

going on.

So in why a shock you can see that traffic was sent from a source IP address 10 1 1 1 to a destination

IP address of 10 1 1 100.

This is HDP traffic.

You can see the protocol they is HDP.

You can see the length you can see that it's an HDP get.

In other words the piece he's trying to get a web page from the server.

Now before I go through the wash capture in more detail let's explain some of the basics that you see

in why shock.

The first thing you see is a frame now in networking.

This is known as Layer two of the oversized model.

Information captured here are known as frames.

So this is known as a frame.

We've captured and Ethernet to frame.

In other words we've captured traffic on Ethernet that different types of Ethan at frames.

But Ethan it too is the most common the source MAC address is a VM where host destination MAC addresses

this.

So the source MAC address is the P.C..

This piece is actually running inside a VM where I type IP conflict slash all you'll be able to see

the MAC address of the host 0 0 0 c 29 ending in DC D 7 and hopefully that's what we see over here.

So notice MAC address is DC D7.

So notice this MAC address is the MAC address of the P.C. destination address is this.

That's the MAC address of the server.

Notice the MAC address over here 36 E four five C 40 91 82.

There you go.

That's the IP address of the server MAC address of the server.

Here's the IP address of the P.C. and the MAC address of the P.C..

So in networking we use the term frame to layer two you get different types of frames on Ethernet typically

Ethan at two.

But on a when connection or wide area network connection you could be using something like point to

point protocol or PDP or HDFC or in the old days you had encapsulation like frame relay or A.T.M..

In other words the layered to frame changes depending on the physical technology that you're using.

Most common technology today's Ethernet most common Ethan at frame type is Ethernet too.

So this is known as a frame not just to make it more confusing in why a shock they talk about frames

here as well but this is actually just metadata used within why shock.

That tells us about the frame.

So again this is just metadata we don't typically talk about that as a frame in networking.

This is known as a frame.

This is known as layer two in the OSA model.

Now I've included a section following this video that talks about ISI and the ISI model.

So if you're not used to the ISI model or you're not quite sure what it's about.

Have a look at those videos.

If you know about the ISI model then skip those videos.

And again if you want more information have a look at my CCN a course.

So this is a frame at least three we have what's called a packet.

So when we refer to the layers in the OS model we use terms such as frame at least two packets layer

three and segment at the layer for at least three we've captured the IP version 4 addresses.

So this is IP version for information.

The protocol used jet layer 4 is IP version for what we'll do actually.

This point is stop my wife's shock capture so that the capture that I share with you isn't too big.

And I'll save this as basic why a shock capture one notice it's a pickup in G file will pick up next

generation Y shock file.

So that's the file that you'll download and you'll be able to do something similar to what I've done

here.

So again protocol at layer 3 is IP version for source IP addresses this destination ip addresses this

IP version 4 contains a lot of information differentiate services code points or differentiate services

field DCP differentiated services code points is to do with quality of service quality of service or

cause or QS allows us to differentiate some traffic types from others.

So in other words we could say that voice traffic is more important than FCP traffic.

So when you make a voice call it should be proud to arised over file transfer protocol or FCP traffic.

This is a way to indicate to the network how important the traffic is.

A lot of other information is shown in this header including as an example that the protocol used at

Layer 4 is TTP.

So lay off for once again this is layered to frame Layer 3 is packet layer forward segment at Layer

4 in the OSA model we are using TTP here and you can see source and destination port numbers HDP or

Hypertext Transfer Protocol uses the well-known port number of 80.

The server was listening on port 80.

That's why when the client made a connection to the server the web page displayed the client initiated

a session to port 80.

The server was listening on port 80.

It served because it's a server.

It served a web page to the client.

In this case using the protocol HDP so it basically has this page.

This web page hosted on its harddrive and it served that page to the client when the client connected

on port 80.

The client uses this random pulled number or ephemeral port number to use the correct term so it connects

to the server using an ephemeral or random port number going to a well-known port number of 80 and then

you can see here the application used his Hypertext Transfer Protocol.

Now in networking we talk about the OS model but typically it's a hybrid model between the TTP model

and the OS side model.

At the top of the other some model we have application presentation and session.

Those layers are often grouped into a single layer called application.

So notice we have Layer 2 here Layer 1 is the physical medium so that's not shown in the wide shot capture

the physical medium here is Ethan it could be copper or could be fiber.

In our example this is just a virtual network.

But in the real world this would be physical Ethernet.

In this case perhaps copper so the physical media is copper.

So that's the physical connection gets just a virtual logical connection.

So layer one physical layer to data link or in this case it's Ethernet Layer three is network.

In this case we've got IP layer four is transport.

In this case it's TTP and then the top three layers are kind of combining to one layer application layer.

So notice Hypertext Transfer Protocol.

And inside here we can see details such as the client used.

It shows up store as windows in t 10 when 64 bit using a browser Mozilla 5.0 so in this example I'm

actually using Microsoft Edge.

That's the browser used within Windows 10.

So this is a Windows 10 a virtual computer.

In other words it's a virtualize.

I'm actually running on a Mac here recording on a Mac but I'm running VMware which allows me to virtualize

multiple devices within my genius free topology.

So the why shock capture sees the client as a Windows 10 computer which is correct using 64 bit Windows

Mozilla is the browser.

It's actually Microsoft Edge and then the server replies back.

Notice in the server example the MAC addresses all swapped round.

In this example I've got a layer to switch a layer to switch means that it's just simply switching trains.

In other words Layer 2 data from one port to another.

It's not trying to rupture the data from one network to another.

These two hosts are in the same subnet or the same network.

So the switch simply switching the traffic from one port to another.

So in this example the IP addresses are swapped round and so are the MAC addresses going back to the

first example.

Notice source MAC address is this destination MAC addresses this when the server replies.

Those are simply stopped around so the server is replying with its MAC addresses the source destination

MAC address is the Windows computer IP addresses a swapped round and so a port numbers and if we look

at the hypertext protocol notice we can see service says 200 Okay 200 means that the server was able

to provide the data to the client.

We didn't have a 4 0 for each team all error.

As an example some data was provided to the client.

Notice you can see here the actual web page that was served to the client so you can see it says network

has toolkit.

You can see the P and G file notice network is toolkit.

And if I look at that web page on the client notice you can see the output here.

It says w w w files located at a var w w w dot HMO and if we look here that's actually what you see.

Files located at var w w w dot HMO.

So if I scroll to the right notice you see the full output.

You get to route after logging in noticed we told you can place files in t t p boot and that's exactly

what you see over here.

So why shock has read the HDP traffic.

Be careful with HDP it's clear text so through why shock you can see exactly what's going on here.

The client is trying to get the G image so it's trying to get the actual P G image and had the server

which is in a boon to server is providing the PMG file so that's the actual file and you can actually

export that and I'd do this again in other videos but let's do it right now.

Genus 3.

Image Some would export that to my desktop and on my desktop I'm going to change that to a PMG file

and then when I open it up notice there's the actual image.

So why shock captured all the data from the server as well as the image.

And that's the image that we have on the server.

So once again to do that click portable network graphics because it's a pinkie file and then go export

packet bytes save it to your hard drive someone to save it once again is genius free image to and then

I'm gonna rename it so it saved it as a burn file.

I'm gonna rename that as P and G because it's a P G file and they want to open it up you can see that

it's say P G file and there's the actual image.

So you can see here it's getting the fave icon and then we're getting something HDP forward for error

something not found.

So something went wrong here.

But the point is is that you can read the actual HDP traffic and remember because of these devices on

the same subnet all that happens is the MAC addresses are swapped around IP addresses or swapped round

port numbers or swapped around during that communication.

So source IP is host yes source IP is the server.

So when the server replies back it's replying back from port 80 to the client.

So that was a very basic example of using Y shock to see what's going on in the network.

Were you able to download the pick up file.

Were you able to open it up in y shock and actually do something similar to what I've done here.

There's no better way to learn than to practically use Y shock capture frames and see for yourself what's

going on.

I've made it a little bit more simple by giving you some pick up files but hopefully they mean something

because she's using the actual files that I'm recording right now rather than just some random file

that you got off the Internet.

Now please note it means a lot to me if you provide feedback on the course.

So if you're enjoying the video then please say so.

If you get prompted to leave a review and you're enjoying the course then please do that because it

helps other students and helps me make the course better let me know how I can improve the course as

well.

Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.